İçeriğe atla
Noroxi

znc kayıtları

znc üreticisine ait 17 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%82,4
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

17 kayıt
  • CVE-2024-39844
    40Planlayın

    In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.

    KritikCVSS 9,8Kavram kanıtıEPSS %4

    3 Tem 2024

  • CVE-2020-29577
    40Planlayın

    The official znc docker images before 1.7.1-slim contain a blank password for a root user.

    KritikCVSS 9,8İstismar yokEPSS %2

    znc · znc docker image8 Ara 2020

  • CVE-2019-12816
    36İzleyin

    Modules.cpp in ZNC before 1.7.4-rc1 allows remote authenticated non-admin users to escalate privileges and execute arbitrary code by loading

    YüksekCVSS 8,8İstismar yokEPSS %4

    znc · znc15 Haz 2019

  • CVE-2009-2658
    31İzleyin

    Directory traversal vulnerability in ZNC before 0.072 allows remote attackers to overwrite arbitrary files via a crafted DCC SEND request.

    YüksekCVSS 7,5İstismar yokEPSS %3

    znc · znc4 Ağu 2009

  • CVE-2010-2488
    31İzleyin

    NULL pointer dereference vulnerability in ZNC before 0.092 caused by traffic stats when there are unauthenticated connections.

    YüksekCVSS 7,5İstismar yokEPSS %2

    znc · znc12 Kas 2019

  • CVE-2019-9917
    27İzleyin

    ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.

    OrtaCVSS 6,5İstismar yokEPSS %3

    znc · znc27 Mar 2019

  • CVE-2009-0759
    27İzleyin

    Multiple CRLF injection vulnerabilities in webadmin in ZNC before 0.066 allow remote authenticated users to modify the znc.conf configuratio

    OrtaCVSS 6,5İstismar yokEPSS %2

    znc · znc3 Mar 2009

  • CVE-2020-13775
    27İzleyin

    ZNC 1.8.0 up to 1.8.1-rc1 allows authenticated users to trigger an application crash (with a NULL pointer dereference) if echo-message is no

    OrtaCVSS 6,5İstismar yokEPSS %2

    znc · znc2 Haz 2020

  • CVE-2018-14055
    26İzleyin

    ZNC before 1.7.1-rc1 does not properly validate untrusted lines coming from the network, allowing a non-admin user to escalate his privilege

    OrtaCVSS 6,5İstismar yokEPSS %1

    znc · znc14 Tem 2018

  • CVE-2018-14056
    22İzleyin

    ZNC before 1.7.1-rc1 is prone to a path traversal flaw via ../ in a web skin name to access files outside of the intended skins directories.

    OrtaCVSS 5,3İstismar yokEPSS %2

    znc · znc14 Tem 2018

  • CVE-2010-2812
    21İzleyin

    Client.cpp in ZNC 0.092 allows remote attackers to cause a denial of service (exception and daemon crash) via a PING command that lacks an a

    OrtaCVSS 5,0İstismar yokEPSS %3

    znc · znc17 Ağu 2010

  • CVE-2010-2934
    21İzleyin

    Multiple unspecified vulnerabilities in ZNC 0.092 allow remote attackers to cause a denial of service (exception and daemon crash) via unkno

    OrtaCVSS 5,0İstismar yokEPSS %3

    znc · znc17 Ağu 2010

  • CVE-2012-0033
    21İzleyin

    The CBounceDCCMod::OnPrivCTCP function in bouncedcc.cpp in the bouncedcc module in ZNC 0.200 and 0.202 allows remote attackers to cause a de

    OrtaCVSS 5,0İstismar yokEPSS %2

    znc · znc-msvc8 Nis 2014

  • CVE-2013-2130
    17İzleyin

    ZNC 1.0 allows remote authenticated users to cause a denial of service (NULL pointer reference and crash) via a crafted request to the (1) e

    OrtaCVSS 4,0İstismar yokEPSS %2

    znc · znc5 Haz 2014

  • CVE-2014-9403
    17İzleyin

    The CWebAdminMod::ChanPage function in modules/webadmin.cpp in ZNC before 1.4 allows remote authenticated users to cause a denial of service

    OrtaCVSS 4,0İstismar yokEPSS %2

    znc · znc19 Ara 2014

  • CVE-2013-7049
    17İzleyin

    Stack-based buffer overflow in fish.cpp in the Fish plugin for ZNC, as used in ZNC for Windows (znc-msvc) 0.206 and earlier, allows remote a

    OrtaCVSS 4,3İstismar yokEPSS %2

    znc · znc-msvc23 Ara 2013

  • CVE-2010-2448
    15İzleyin

    znc.cpp in ZNC before 0.092 allows remote authenticated users to cause a denial of service (crash) by requesting traffic statistics when the

    DüşükCVSS 3,5İstismar yokEPSS %2

    znc · znc12 Tem 2010